logo

Researchers Warn Of PamDOORa Backdoor Attacking Linux Systems

ID: 73941cdb-8801-532a-a6ba-6d0abb177a42

STIX ID: report--73941cdb-8801-532a-a6ba-6d0abb177a42

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: Varshini

...
...

The report describes PamDOORa, a stealthy Linux persistence/backdoor that abuses the PAM pam_exec module to execute hidden scripts during SSH authentication (notably on failed logins), harvest environment variables (e.g., PAM_RHOST, PAM_SERVICE, PAM_USER) and exfiltrate them to attacker-controlled servers; the technique evades standard logs and detection, and the report recommends strict file integrity monitoring and Linux hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.